What you govern, and the risk on it.

Business units, apps, vendors, processes, and AI agents live in one inventory. Put an app under the business unit that owns it, or at the company with no business unit. Each one carries its own compliance and residual risk, and those roll up.

Inventory · Acmeillustrative
ItemWhere it sitsComplianceResidual risk
AcmeCompany81% passing$640K
EngineeringBusiness unitPartial$450K
Customer portalApp, under EngineeringPartial$410K
Data warehouseApp, under EngineeringPassed$40K
Employee laptopsCompany level, 10,000 as oneOne assessment$120K
StripeVendor, Tier 1, owned by FinanceIn progress$70K
Corporate identityApp, company levelPassed$0
$640Kresidual risk, the sum of the itemsEvery itemwith its own integrations and Data Room
Illustrative example

TruOps keeps an inventory of what you govern. An app can sit under the business unit that owns it, and that business unit’s compliance and residual risk are the sum of the apps under it. A vendor can be tied to several apps and processes at once, with its own owner and its own result. Company-wide apps, such as identity, sit at the company with no business unit, and roll straight up. Assess any item, or a group of the same assets. The result is saved on that item: compliance status, open findings, and residual risk in dollars, from likelihood, impact, and the controls in place. A person approves the score.

Where an item sits
Under a business unit, under a vendor, or at the company
Also tied to
The apps, processes, and vendors it depends on
Written back
Compliance, findings, and residual risk in dollars
Rolls up
From an app to the company

What you're probably using today

What you use nowWhere it falls shortWith TruOps
Spreadsheets, shared drives, and emailYour program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork, and nothing is dated, so you can't show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so you have evidence for the whole period.
Enterprise GRC suitesThey can model almost anything, but that flexibility usually runs through implementation partners and admins, so every change turns into a project.AI reads your existing documents and sets up the program. Your first assessment opens pre-filled with sources, and you make changes by asking in plain language.
Point tools that don't connectA TPRM portal here, a risk register there, findings in your ticketing tool, and the board pack in slides. Each tells its own story, so leadership gets three different answers.One place for assessments, evidence, and risk. Upload a document, answer a question, or check a control once, and it counts everywhere it applies.

Where each item sits

Ownership and dependence are different ties. A business unit owns the apps and processes that belong to it. A vendor can serve several of those at once, and still have its own owner. Anything that belongs to the whole company sits at company level, with no business unit.

ItemWhere it sitsAlso tied to
Customer portalEngineeringThe payments vendor, and the refunds process
Data warehouseEngineeringFinance, for the close
Corporate identityThe companyEvery business unit that signs in
Employee laptopsThe company, as one groupThe people who use them
Payments vendorVendor, owned by FinanceThe portal and the refunds process

The assessment stays on the item

When an assessment finishes, its result is written onto the item it covered. Compliance status, open findings, and the date sit there. A risk assessment adds likelihood, impact, and a dollar figure for what remains after controls. Every dollar opens to the evidence behind it. A person approves the score before it is final.

The company number is the sum

A failed control on a server is visible on that server, on the app it belongs to, on the business unit, and on the company. Fifty servers failing the same check become one finding that lists all fifty. Residual risk in dollars rolls up the same path, so the company figure is the sum of the items under it.

The same assets, assessed once

Ten thousand laptops are one thing to assess. A group can follow a rule, such as every server in production, so new ones join on their own. The group carries one result, and its findings and dollars still roll up.

Kept current

Connect the tools that already list what you run. TruOps builds the inventory from them and keeps it current. You can also bring in a spreadsheet, add an item by hand, or add a type of your own, such as a data center, a contract, or an office.

How TruOps helps

Where it sits
Under a business unit, under a vendor, or at the company with no parent.
More than one tie
An app can relate to a vendor and a process as well as the unit that owns it.
Results on the item
Compliance, open findings, and residual risk in dollars, from the assessment.
Roll-up
From an app to the business unit, and the company.
Groups
Look-alike assets assessed once, including by a rule that new ones join.
Your own types
Data centers, contracts, offices, or anything else you govern.

Questions

What can go in the inventory?

Apps, vendors, business units, processes, and AI agents, plus any type you add, such as projects, data centers, contracts, or offices. An item can sit under a business unit, under a vendor, or at the company.

Does every item have to sit under a business unit?

No. Company-level items have no business unit. Others sit under the business unit or vendor that owns them.

Can one item relate to more than one other?

Yes. Ownership is one tie. A vendor can also be tied to the apps and processes that depend on it, and an app can be tied to more than one of those.

Where do the dollar figures come from?

From the risk assessment on that item: likelihood, impact, and the controls in place. The dollars roll up to the business unit and the company. A person approves the score, and every figure opens to the evidence behind it.

Do we have to assess thousands of servers one by one?

No. Group look-alikes and assess the group once. A group can follow a rule, such as Environment is Production, so new servers join on their own.

Can it find AI tools nobody approved?

Connect Okta or Entra and TruOps lists the AI tools your people sign in to, including ones nobody approved, next to the agents built on your own platforms.

Do we have to rip out the tools we already use?

No. TruOps connects to your cloud, identity, endpoint, vulnerability, and code tools. Spreadsheets, prior reports, and policies upload into the Data Room. If you're moving from a SOC 2 automation tool or an enterprise GRC suite, you bring over your frameworks, evidence, vendors, and risks.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and risks, each linked to the file it came from, for you to review.

See it run on your own data.

Book 30 minutes with a GRC specialist. Bring a real document, like a SOC 2 report, risk register, or vendor list (redacted is fine), and we'll show TruOps AI working on it.